如何启用K8s主节点的NodePort服务路由功能?
Let’s walk through getting your master node to route NodePort service traffic just like your slave nodes do. Here are the key checks and fixes tailored to Kubernetes v1.8.6:
1. Ensure kube-proxy is running on the master node
kube-proxy is responsible for setting up the network rules that route NodePort traffic to your pods.
- First, check if a kube-proxy pod is running on your master:
kubectl get pods -n kube-system | grep kube-proxy - If there’s no kube-proxy pod for your master, check the kube-proxy DaemonSet configuration—sometimes it’s set to only run on worker nodes:
kubectl get daemonset kube-proxy -n kube-system -o yaml | grep -A 5 nodeSelector- If you see a
nodeSelectorthat excludes master nodes (likenode-role.kubernetes.io/node: ""), either remove that selector from the DaemonSet, or add the required label to your master node:kubectl label node <your-master-node-name> node-role.kubernetes.io/node=true - After making changes, the DaemonSet will automatically spawn a kube-proxy pod on the master.
- If you see a
2. Verify iptables rules and IP forwarding
Kubernetes uses iptables to route NodePort traffic. Let’s make sure the rules are in place:
- On your master node, check for the specific NodePort rule (replace
30141with your service’s NodePort):iptables-save | grep 30141 - If you don’t see any rules for that port, restart the kube-proxy pod to regenerate them:
kubectl delete pod <kube-proxy-pod-name> -n kube-system - Also, ensure IP forwarding is enabled on the master—this is required for traffic routing:
sysctl net.ipv4.ip_forward- If the output is
net.ipv4.ip_forward = 0, enable it temporarily:sysctl -w net.ipv4.ip_forward=1 - To make this permanent, add
net.ipv4.ip_forward=1to/etc/sysctl.confand runsysctl -p.
- If the output is
3. Check firewall/security group settings
Even if the Kubernetes rules are correct, your master node’s firewall or cloud security group might be blocking NodePort traffic:
- For Linux firewalls (like
ufworfirewalld), allow the NodePort range (default is 30000-32767) and your service’s target port (e.g., 5601 for Kibana):- For
ufw:ufw allow 30000:32767/tcp ufw allow 5601/tcp - For
firewalld:firewall-cmd --add-port=30000-32767/tcp --permanent firewall-cmd --add-port=5601/tcp --permanent firewall-cmd --reload
- For
- If you’re using a cloud provider, update your master node’s security group to allow inbound traffic on the NodePort (30141 in your example) from your desired source IPs.
4. Confirm kube-proxy's operating mode
In v1.8.6, kube-proxy can run in iptables or userspace mode. userspace mode is less reliable for NodePort routing, so we want to ensure it’s using iptables:
- Check the kube-proxy ConfigMap:
kubectl get configmap kube-proxy -n kube-system -o yaml - Look for the
modefield in theconfig.confsection. If it’s set touserspace, update the ConfigMap to useiptablesinstead, then restart all kube-proxy pods:kubectl delete pods -n kube-system -l k8s-app=kube-proxy
After going through these steps, your master node should be able to route traffic to NodePort services just like your slave nodes do.
内容的提问来源于stack exchange,提问作者Silk0vsky

